MCP security report

agents.haveitprinted.com

B85/100
Security grade BA few things are worth a closer look before connecting.
Connected ✓10 tools scanned

https://agents.haveitprinted.com/mcp

mediumhip_complete_payment
References secrets or data exfiltration
The tool text references credentials, environment variables, or sending data elsewhere. This can be legitimate, but review what this tool actually accesses.
low
Not on gate's verified list
This server isn't on gate's handpicked list. That's not necessarily bad, but there's no third-party signal about it — review its tools carefully.
lowhip_complete_payment
Autonomous payment rail without explicit user confirmation step in schema
The tool allows fully autonomous payment via a delegated token with no browser/human step. While it correctly warns never to send raw card data and relies on opaque tokens, the overall design (hip_prepare_payment + hip_complete_payment) enables an agent to complete a real monetary charge without any built-in requirement that the human user has seen/approved the final quote. This is a reasonable design if the delegated authorization itself implies consent, but it's worth flagging as a capability that could be misused if the agent skips showing the quote to the user, since nothing in the schema enforces that step (it's only advisory text in hip_create_checkout, not in the payment tools).
Embed this badge

Show your MCP server’s security grade

MCP security grade B

Paste this into your README:

[![MCP security](https://gateturbo.com/badge/scan/4605c166-bc63-4957-a00a-2b39c0451d4d)](https://gateturbo.com/report/4605c166-bc63-4957-a00a-2b39c0451d4d)

Scanned 9/12/2026 · This is a point-in-time snapshot of the server’s public tools. Re-scan.

Connect this server safely with gate.

Continuous re-scans, drift alerts, per-tool allow/ask/block, and a log of every call.

Monitor it — free